Skip to main content

How to use dsh-secret-scan

Scans codebases recursively for leaked keys, tokens, private keys, and hardcoded passwords, then redacts sensitive output.

This article is auto-derived from indexed fields (wiki / faq / compatibility_json), not freshly AI-generated.

This article is derived from the plugin's already-indexed fields (wiki / faq / compatibility_json / readme), not freshly generated by AI. Source field is noted at the end of each section.

Quick start

Scans codebases recursively for leaked keys, tokens, private keys, and hardcoded passwords, then redacts sensitive output.

— source: plugins.ai_summary

Install & verify

dsh plugin --profile web add dsh-secret-scan

Run the command above in your DSH Web Profile. Then enable the plugin in the plugin list.

— source: plugins.install

Pitfalls

Review the upstream repo before installing. This guide is auto-derived from indexed fields and may lag the latest release. If anything contradicts the official docs, treat the upstream source as authoritative.

— source: general rule